JobRaahGet matched free

Jobs

Senior Third-Party Risk Management Analyst

communitybrands · Remote (US Only) · United States · Remote

Posted Oct 7, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

Job Description POSITION OVERVIEW The Third-Party Risk Management (TPRM)Analyst serves as a core member of Momentive Software's Cybersecurity, Risk & Compliance organization. This role is responsible for maintaining and maturing Momentive's enterprise-wide third-party risk program, ensuring that all vendors, platforms, and service providers meet the Firm's cybersecurity, privacy, resiliency, and regulatory requirements. The Analyst partners closely with Client Success, Cybersecurity Engineering, TVM, Legal, Procurement, Product, and the CISO to evaluate vendor risk, maintain continuous oversight of third-party controls, and support Momentive's compliance obligations — including SOC 2 Type II and PCI DSS. The role also supports TVM notifications to clients who manage their own cybersecurity posture, ensuring clear, accurate, and timely communication of vulnerabilities and remediation expectations. This position requires strong analytical capability, deep familiarity with cybersecurity frameworks, and the ability to translate complex risk issues into actionable guidance for business and technical stakeholders. KEY RESPONSIBILITIES Third-Party Risk Management Program Maintain Momentive's global inventory of third-party providers, applications, and services from onboarding through termination. Lead vendor cybersecurity assessments, coordinating with Cybersecurity Engineering, Legal, and business owners to evaluate risk and required controls. Assess vendor maturity using NIST CSF, CIS, CMMC, GDPR, PCI DSS, SOC 2, and other frameworks. Oversee vendor SLAs, RPO/RTO commitments, breach notification requirements, and cybersecurity insurance documentation. Ensure thorough documentation of findings, recommendations, and remediation plans for all vendor assessments. Serve as a liaison to internal and external auditors for vendor-related controls and evidence collection. Support for PCI DSS & SOC 2 Type II Audits Provide evidence, documentation, and control validation related to third-party dependencies for Momentive's SOC 2 Type II and PCI DSS assessments. Ensure vendor controls align with Momentive's ISMS, contractual obligations, and certification requirements. Partner with the GRC team to maintain audit-ready documentation, including policies, standards, procedures, and risk treatment plans. Track vendor exceptions and compensating controls, ensuring audit defensibility and continuous improvement. TVM Notifications & Client Support Collaborate with the Threat & Vulnerability Management (TVM) team to support vulnerability notifications to clients who manage their own cybersecurity controls. Ensure communications are accurate, timely, and aligned with Momentive's contractual commitments and industry best practices. Provide consultative guidance to clients regarding risk impact, remediation expectations, and recommended cybersecurity practices. Maintain documentation and metrics related to client notifications,…